Information Security Risk and Compliance Analyst
Richmond, VA - USA
Job Summary
Title: Information Security Risk and Compliance Analyst
State Role Title:Info Technology Specialist II
Hiring Range: $85000 - $110000; Commensurate with experience
Pay Band: 5
Agency: Department of the Treasury
Location:JAMES MONROE BUILDING
Agency Website:
Recruitment Type: General Public - G
Job Duties
Are you passionate about cybersecurity and keeping systems that support the Commonwealth Treasury and ultimately the State secure Are you curious analytical and motivated to learn and interested in an opportunity to grow your cybersecurity expertise while serving the Commonwealth
The Virginia Department of the Treasury is dedicated to serving the Commonwealth by providing excellent management of its banking investing and financing services and the administration of unclaimed property and insurance programs.
We are seeking a motivated and detail-oriented Information Security Risk and Compliance Analyst to support the agencys cybersecurity and risk management operations. This position plays a critical role in protecting the Commonwealths financial systems sensitive data and technology infrastructure.
This is a mid-level role designed for someone who is building their cybersecurity career and has experience in compliance and risk management within a government environment.
The key responsibilities of the Information Security Risk and Compliance Analyst are:
Application Security
Create and maintain System Security Plans
Define security acceptance criteria that align with business requirements and security policies
Document requirements for test environment and test accounts
Develop and document test cases
Execute security related test cases
Support multi-factor authentication (MFA) and other identity verification mechanisms to strengthen access security.
Security Awareness & Training
Develop implement and manage security awareness programs to educate employees on cybersecurity best practices.
Create training materials presentations and campaigns that effectively communicate security policies and procedures.
Analyze training metrics and reporting to identify gaps and continuously improve program effectiveness.
Maintain familiarity with emerging threats and trends to keep awareness content current and relevant.
Manage Treasurys annual training campaign to ensure compliance with SEC 527 and other relevant Commonwealth Standards.
Risk Management
Identify threats and vulnerabilities
Create and maintain risk assessments
Manage Archer and other applicable risk registers
Track remediation activities and corrective action plans
Governance Compliance and Audit Support
Verify alignment with Commonwealth of Virginia Information Security NIST and other applicable Standards
Coordinate internal and external compliance audits
Build and update security policies and procedures
Maintain security documentation
Develop reports and dashboards for leadership as requested
Minimum Qualifications
The selected candidate will possess the following qualifications:
Understanding of cybersecurity principles including:
o Network security fundamentals
o Access control concepts
o Malware and phishing threats
o Incident response basics
Knowledge of NIST security frameworks and compliance standards
Experience developing System Security Plans in accordance with SEC 530 Standard or similar
Excellent written communication skills.
Strong analytical and problem-solving skills.
Ability to document findings clearly and concisely.
Strong attention to detail and organizational skills.
Ability to handle sensitive and confidential information appropriately.
Experience working with development teams to develop and execute application security test plans.
Strong understanding of Role-Based Access Control (RBAC) Least Privilege Principles and Segregation of Duties.
Familiarity with Multi-Factor Authentication (MFA) and Single Sign-On (SSO) technologies.
Additional Considerations
Familiarity with common Governance Risk and Compliance security tools such as Archer.
Experience in Information Security Identity and Access Management (IAM)
Experience in monitoring third-party risk.
Familiarity with cloud environments (AWS Azure GCP) and their access control mechanisms.
Experience working in a government or highly regulated environment
Special Instructions
You will be provided a confirmation of receipt when your application and/or résumé is submitted successfully. Please refer to Your Application in your account to check the status of your application for this position.
A résumé and cover letter are required to be submitted. Applications for this position must
be submitted electronically through this website.
The Department of the Treasury telework policy allows for up to two days a week of telework subject to the position requirements. This position will be located in Richmond Virginia and must report on-site until the completion of an approved telework agreement is received.
All finalists are subject to a background investigation. The investigation may include: criminal checks; employment verification; verification of education; and other checks requested by the hiring authority.
Applicants who possess an Interagency Placement Screening Form (Yellow Form) or a Preferential Hiring Form (Blue Form) as issued under the Department of Human Resources Management (DHRM) Policy 1.30 Layoff (Commonwealth of Virginia Employees Only) must attach these forms with their state application.
Mailed emailed faxed or hand delivered applications and résumés will not be accepted.
This website will provide a confirmation of receipt when the application is submitted for consideration.
Please refer to your RMS account for the status of your application and this position.
The Virginia Department of the Treasury is an Equal Opportunity Employer.
Contact Information
Name: Lori Perez
Phone:
Email:
In support of the Commonwealths commitment to inclusion we are encouraging individuals with disabilities to apply through the Commonwealth Alternative Hiring Process. To be considered for this opportunity applicants will need to provide their AHP Letter (formerly COD) provided by the Department for Aging & Rehabilitative Services (DARS) or the Department for the Blind & Vision Impaired (DBVI). Service-Connected Veterans are encouraged to answer Veteran status questions and submit their disability documentation if applicable to DARS/DBVI to get their AHP Letter. Requesting an AHP Letter can be found at AHP Letter or by calling DARS at .
Note: Applicants who received a Certificate of Disability from DARS or DBVI dated between April 1 2022- February 29 2024 can still use that COD as applicable documentation for the Alternative Hiring Process.
Required Experience:
IC
About Company
The official website of the Commonwealth of Virginia. Learn about Virginia government, contact a state agency, and find the services and resources you need.